R2-D2
Dashboard
Node Red
Restreaming
The Force
UpdatedNever
v1.0.0

Overview

Loading…
R2-D2
Dashboard
Node Red
Restreaming
The Force
UpdatedNever
v1.0.0
DDroidspeak / Docs
Operator handbook
Droidspeak
What is R2-D2?
Runtime architectureAuth — Keycloak migration plan
FleetRestreamingGalaxy MapThe RepublicTemple ArchivesSTANAG 4817The Force
Tech StackNext.js 15 + React 19Tailwind v4ZustandTanStack Table + DataViewhls.jsLow-latency playerreagraphoglreact-grid-layoutMonacoScalar API Referencefumadocs
Cluster InfraTrailBaseReductStoreRestreamer (datarhei/core)TBMQKeycloakLonghornkube-vipIngress (Caddy + nginx-ingress + Traefik)Netbird
Operator QA Runbook
Install — RKE2Install — Dokploy
Contributor guideRelease Notes
Cluster Infra

Keycloak

OIDC identity — R2-D2 theme, hardened realm, and the dashboard's auth integration.

Keycloak is the dashboard's identity provider. It runs in-cluster, ships a custom R2-D2-branded login theme, and integrates with the dashboard via a standard OIDC client (PKCE S256, backchannel + frontchannel logout, refresh tokens).

Where it sits

Chart / valueskeycloak/ in the parent repo
Themekeycloak/themes/r2d2/
Realm exportkeycloak/realms/r2d2-realm.json
CI guardkeycloak/scripts/verify-theme.sh
Client IDr2d2-fleet

The R2-D2 theme

Same palette as the dashboard (see Tailwind v4):

  • Background #0a0e1a, surface rgba(17, 24, 39, 0.78), accent #2dd4bf.
  • Login backdrop: radial-gradient blooms + SVG starfield tiles with 240s parallax drift (CSS-only, no JS).
  • 3px tri-tone (teal → blue → violet) brand bar in body::before.
  • Wordmark "R2-D2 Fleet", tagline "Astromech Fleet Console".
  • Redirect copy: "Boarding the fleet in N seconds…".
  • Astromech "online" pulsing teal dot via .r2d2-tagline::before.

A11y: :focus-visible (teal on dark, white on primary), prefers-reduced-motion, prefers-contrast: more, forced-colors, and @media print all handled.

Easter egg

Inside login/template.ftl <body>:

<!-- These aren't the droids you're looking for. Move along. -->

Realm hardening

SettingValue
Brute forceon — failureFactor 8, max-wait 15m
Password policylength(12) + lower + upper + digit + notUsername + notEmail + history(5) + argon2
TOTPHmacSHA1, 6 digits, 30s
EventseventsEnabled + adminEventsEnabled
SMTPplaceholder with env interpolation
Default role assignmentdefault-roles-r2d2 → pending for new signups
Required actionsVERIFY_EMAIL, UPDATE_PASSWORD, CONFIGURE_TOTP enabled
Client r2d2-fleetPKCE S256, refresh tokens, 8h idle/max session

Email

Dark theme matches the dashboard. Card #111827 on #0a0e1a, teal #2dd4bf buttons on #04221d. JetBrains Mono OTP card with teal border. Hidden 1px preheader. Outlook-specific fallbacks: [if mso] Arial, x-apple-disable-message-reformatting, format-detection off.

Don't reintroduce orion

The R2-D2 rebrand is regression-guarded by verify-theme.sh. Do not reintroduce:

  • orion-* class names
  • --orion-* CSS variables
  • NATO ORION strings
  • orion.office.ilab.zone hostnames
  • nato-orion chart names

The script fails CI on any of those reappearing, on a realm JSON parse failure, or on a logo SHA drift versus r2d2-fleet/public/image.png.

How the dashboard verifies tokens

The dashboard uses jose to verify Keycloak-issued JWTs server-side. Auth-gated route handlers pull the access token from the session cookie, verify against Keycloak's JWKS, and reject on signature / expiry / audience failure.

Deploy handoff

.settings/features/keycloak-r2d2-rebrand/DEPLOY.md (private — not in the docs site) has the kcadm import, compose snippet, env vars, and sanity tests.

See also

  • Tailwind v4 — shared palette
  • Next.js + React — jose verification path
  • Architecture

TBMQ

The MQTT broker R2-D2 uses for Temple Archives feed-sync and the HoloNet topic explorer.

Longhorn

Block storage — PVCs, csi-attacher leader recovery, and Multi-Attach error decoding.

On this page

Where it sitsThe R2-D2 themeEaster eggRealm hardeningEmailDon't reintroduce orionHow the dashboard verifies tokensDeploy handoffSee also